Changes between Initial Version and Version 1 of Ticket #2213


Ignore:
Timestamp:
May 18, 2022, 3:51:01 PM (4 years ago)
Author:
Torsten Riemer
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #2213 – Description

    initial v1  
    11In der tracking.php werden in Zeile 37 und 40 zwei GET Parameter ungefiltert in die Session geschrieben.
    22Never trust an external parameter :)
    3 
    4 $_SESSION['tracking']['refID'] = $_GET['refID'];
     3{{{
     4    $_SESSION['tracking']['refID'] = $_GET['refID'];
    55    $sql_data_array = array(
    66      'user_ip' => ip_clearing($_SESSION['tracking']['ip']),
     
    88      'time' => 'now()'
    99    );
     10}}}